Case studies

MedTech · Compliance and process automation

Security questionnaires answered in one week instead of one month

Every hospital that wanted apoQlar’s medical AR platform first required a completed security questionnaire, with tens or hundreds of questions about data protection, compliance and technical security. Answering one took a month and eight to ten people. A GenAI assistant now does it in under a week with a small verification team.

Key results

–75%
Completion time, from about a month to under a week
$90K
Estimated saving a year across roughly 15 questionnaires
6 → 2 wks
Client onboarding cut by two thirds
8 → 2
People involved, from eight to ten down to a verification team

Client: apoQlar
A MedTech company in Hamburg developing mixed reality and AI for healthcare. Their platform brings holographic imaging into the operating theatre.

apoQlar
Industry
MedTech
Use case
Security questionnaire automation
AI approach
RAG and LLM on Azure
Data source
PDF policies, Confluence
Output
Source-referenced answers
Product
Zippy (theBlue.ai)

In short

A month of committee work, replaced by one person verifying

  • Every hospital client demanded a security questionnaire with tens or hundreds of questions before they would adopt apoQlar’s platform.
  • Answering one took a month and eight to ten people from IT, legal, compliance and product, although the answers already existed in internal documents.
  • A retrieval assistant on Azure now drafts every answer with the document name and page it came from, so one person can verify instead of ten searching.
  • Completion dropped to under a week, client onboarding from six weeks to two, and the saving is around $90,000 a year.

The starting point

The challenge

Every new hospital client required a completed security questionnaire that took a month and eight to ten people, although most answers already existed somewhere in the company’s own documentation.

Before a hospital can adopt a MedTech product, the vendor has to demonstrate compliance with strict security and data protection standards. In practice that means filling out questionnaires with tens or hundreds of questions about encryption, access controls, incident response, vulnerability management and internal policies.

At apoQlar each questionnaire needed input from eight to ten people across IT, legal, compliance and product. Someone had to locate the right policy document, find the relevant section, formulate an answer and get it reviewed. With everyone working to their own schedule, one questionnaire took about a month.

At roughly 15 new hospital onboardings a year, this was a permanent drain on the team and the single biggest bottleneck in the sales cycle.

The build

What we built

We built Zippy, a GenAI assistant that answers security questionnaires from apoQlar’s own documentation. Instead of eight to ten people searching through policies and Confluence pages, one person runs the questionnaire through Zippy and verifies the results.

01

Retrieval on the company’s own documents

The system connects a language model to apoQlar’s complete document base: security policies stored as PDFs and technical documentation from Confluence. Azure OpenAI Services power the model, ChromaDB serves as the vector database. All processing stays inside Microsoft Azure, which is what enterprise security requires.

02

Every answer names its source

Each response carries the exact document name and page number it came from. For compliance work that matters: the person verifying can check where an answer originated instead of trusting an opaque output. It also makes verification far quicker.

03

Document processing built for each format

Policy PDFs and Confluence pages arrive in very different shapes. We developed extraction and chunking strategies for each source that preserve structural context and metadata, so retrieval finds not just the relevant text but the specific section and page in the original document.

04

Feedback that improves the documentation too

Users flag inaccurate answers directly in the interface. LangFuse tracks that feedback along with prompt versions, cost and latency. Where Zippy answers poorly, it surfaces a gap in the documentation, which gives the teams a reason to keep their policies current.

Security questionnaires answered in one week instead of one month

What changed

The results

Before

About a month per questionnaire. Eight to ten people from IT, legal, compliance and product searched through policies and Confluence by hand, and every new hospital onboarding waited on them.

After

Under a week per questionnaire. One person runs it through Zippy and a small team verifies, with every answer carrying the document and page it came from. Client onboarding went from six weeks to two.

Completion time dropped by 75 percent, the number of people involved fell from eight to ten down to a small verification team, and the estimated saving across roughly 15 questionnaires a year is around $90,000 in labour alone.

The commercial effect is larger than the labour saving. Client onboarding went from six weeks to two, which directly accelerates how fast apoQlar can put their solution into hospitals.

The feedback loop produced something nobody planned for. Because Zippy shows which questions it cannot answer well, apoQlar now sees where their documentation is incomplete, and that improves the policies independently of any questionnaire.

Managing the completion of security questionnaires is no longer a logistical nightmare. The new system is easy to manage and ensures our responses are accurate and comprehensive.
Maciej Antoszczuk Tech Product Owner, apoQlar

Questions about this project

Security questionnaire automation. Every new hospital client required a completed security questionnaire that took a month and eight to ten people, although most answers already existed somewhere in the company’s own documentation.

Completion time, from about a month to under a week: –75%. Estimated saving a year across roughly 15 questionnaires: $90K. Client onboarding cut by two thirds: 6 → 2 wks. People involved, from eight to ten down to a verification team: 8 → 2.

RAG and LLM on Azure. Technology used: RAG architecture, Azure OpenAI Services, ChromaDB, LangChain, LangFuse, Streamlit, Python, Confluence integration, PDF processing.

Technology used

RAG architecture Azure OpenAI Services ChromaDB LangChain LangFuse Streamlit Python Confluence integration PDF processing

Talk to the people who built this

theBlue.ai comes back within one business day.

Contact us